|
247361
|
7.5 |
HIGH
Network
|
eclipse
|
mojarra
|
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Ja…
|
CWE-22
Path Traversal
|
CVE-2018-14371
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247362
|
8.8 |
HIGH
Network
|
techsmith
|
mp4v2
|
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-14379
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247363
|
7.5 |
HIGH
Network
|
debian neomutt
|
debian_linux neomutt
|
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
|
CWE-22
Path Traversal
|
CVE-2018-14363
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247364
|
9.8 |
CRITICAL
Network
|
mutt neomutt canonical debian redhat
|
mutt neomutt ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus
|
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14362
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247365
|
9.8 |
CRITICAL
Network
|
debian neomutt
|
debian_linux neomutt
|
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
|
CWE-20
Improper Input Validation
|
CVE-2018-14361
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247366
|
9.8 |
CRITICAL
Network
|
debian neomutt
|
debian_linux neomutt
|
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14360
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247367
|
9.8 |
CRITICAL
Network
|
mutt neomutt canonical debian
|
mutt neomutt ubuntu_linux debian_linux
|
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-14359
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247368
|
9.8 |
CRITICAL
Network
|
mutt neomutt canonical debian
|
mutt neomutt ubuntu_linux debian_linux
|
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14358
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247369
|
9.8 |
CRITICAL
Network
|
debian mutt neomutt canonical
|
debian_linux mutt neomutt ubuntu_linux
|
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2018-14356
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247370
|
5.3 |
MEDIUM
Network
|
debian mutt neomutt canonical
|
debian_linux mutt neomutt ubuntu_linux
|
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
|
CWE-22
Path Traversal
|
CVE-2018-14355
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|